Roles & Responsibilities
Overview Network Information Assurance specialist support Enterprise-class networks in the day-to-day operations in support of Computer Network Defense (CND), whose function is to deny adversaries access to information and information systems. The Network Information Assurance specialist is responsible for the operation and maintenance (O&M) of the technologies, to include, troubleshooting, optimization, administration, change management and technical documentation. The core network technology utilized is the McAfee Network Security Platform, which includes the Network Security Manager (NSM) and the physical Intrusion Prevention System appliances. Program: OMDAC-SWACA You must satisfy all host country requirements to legally work in the host country in order to be qualified for this position. Responsibilities Provide enterprise-level O&M support as part of the DoDIN Defense-in-Depth strategy. This includes ensuring the NSM stays viable in its reporting capability as well as understanding, identifying and resolving varied appliance disconnects. Additionally, analysts develop an understanding of current and future attacks which will assist in determining the difference between a bonafide attack, verified suspicious or nuisance reconnaissance, and normal network noise. Perform blocking of Internet protocol (IP) networks when directed by the Government. Monitor, operates, and maintain network-based Intrusion Prevention System (IPS) sensors. Investigate possible network and Automated Information System (AIS) security events. Generate reports and update trouble tickets as required. Provide O&M support of the McAfee Network Security Platform (NSP), Network Security Manager (NSM) servers and IPS sensors (GUI and CLI). Analyze stock IPS alerts on all enclaves to ascertain if the alert should be put into block status. Create Access Control Lists (ACLs) (e.g. Firewall Policies) in the McAfee NSM for IP whitelisting. Develop custom IPS signatures using McAfee and/or Snort rule format in response to a recent or potential intrusion; or in response to security research performed by members of the IPS team for preventative measures. Perform in depth analysis using SIEM to include but not limited to: Reports, Queries, Active Channels, Active Lists, Integration Commands, Data Monitors, Dashboards, Filters, Correlation Development using Rules, etc. Analyze potentially malicious traffic at the packet level using Wireshark. Respond to potentially malicious installed files on remote hosts by pulling down files via remote desktop for analysis, discovering what services are running on the remote host via command line, etc. Participate in CND exercises as requested by the Government to provide configuration and analysis of IPS alerts. Elevated account management of RCC-SWA personnel including certification validation and Army Training and Certification Tracking System (ATCTS) utilization. Utilize endpoint software to map software applications throughout the enclaves as well as to ensure appropriate versioning. Qualifications Minimum Qualifications Bachelors Degree or equivalent experience preferably in Computer Science or MIS, IS, Engineering or related field. One-year related experience can be substituted for one year of education if the degree is required. One year of related academic study above the high school level may be substituted for one year of experience up to a maximum of a 4-year bachelor's degree in a Software Engineering or Business Information Systems discipline for three years general experience. Experience: Minimum of (5) years' of experience in administrative, technical work, which demonstrated the ability and aptitudes, required to perform technical, managerial, or analytical work and coordination involving management information systems. Platforms including a combination of the following: Platforms including a combination of the following: McAfee Network Security Manager, McAfee Intrusion Prevention System appliances, Microsoft Server, Networking and WireShark. Certifications: This position requires candidates to adhere to DoD 8570.01-M. All candidates are required to maintain at least one (1) baseline certification and one (1) computing environment (CE) certification. The authorized certifications for this job title are listed as follows: IAT Level: IAT III Baseline: Cisco CCNP Security CompTIA CASP ce GIAC GCED GIAC GCIH ISACA CISA ISC2 CISSP (or Associate) CE: Cisco: CCIE - Certified Internetwork Expert - (Any) Cisco: CCNP - Certified Network Professional - (Any) Microsoft: MCSA - Cloud Platform Microsoft: MCSA - Certified Solutions Associate Windows Server 2012 Microsoft: MCSA - Certified Solutions Associate Windows Server 2016 Microsoft: MCSE - Cloud Platform and Infrastructure Microsoft: MCSE - Data Management and Analytics Microsoft: MCSE - Productivity Solutions Expert We are committed to an inclusive and diverse workplace that values and supports the contributions of each individual. This commitment along with our common Vision and Values of Integrity, Respect, and Responsibility, allows us to leverage differences, encourage innovation and expand our success in the global marketplace. Vectrus is an Equal Opportunity /Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, protected veteran status or status as an individual with a disability. EOE/Minority/Female/Disabled/Veteran.